MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52fc1d5e31b7661dd3063f2529bbd555b4649a80dc20e7170a359a732f443ef6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 52fc1d5e31b7661dd3063f2529bbd555b4649a80dc20e7170a359a732f443ef6
SHA3-384 hash: 757dc5b5c603db73755174c420eed0c4964367cf005d1932904dfbf21de9af9fff4c1355b4c5a0f8d07d0b6ef704b394
SHA1 hash: 442ccb211352ad00dd482bd1e0aeb5a89c14c0b1
MD5 hash: 451baeea7e68150a43a653badddcb78f
humanhash: bacon-texas-single-lake
File name:Invoices.zip
Download: download sample
Signature AgentTesla
File size:461'705 bytes
First seen:2020-07-27 22:24:37 UTC
Last seen:2020-07-28 01:28:23 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:lz9n2JI8JdhpUHnA3AwW81pX2jjp6q8BeAN:D2btaHn+WopGHmBLN
TLSH 5DA4231959B444F843A7DBB6D0FF4D092F6A3365546BC6E682AB036C10BD0E1C1BDCB9
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-26 18:56:16 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 52fc1d5e31b7661dd3063f2529bbd555b4649a80dc20e7170a359a732f443ef6

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments